Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-32274 — Black: Arbitrary file writes from unsanitized user input in cache file name

Black is the uncompromising Python code formatter. Prior to 26.3.1, Black writes a cache file, the name of which is computed from various formatting options. The value of the --python-cell-magics opt…

| Misconfiguration
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32269 — Parse Server OAuth2 adapter app ID validation sends wrong token to introspection endpoint

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.13 and 8.6.39, the OAuth2 authentication adapter does not correctly valida…

| Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32260 — Command Injection via incomplete shell metacharacter blocklist in node:child_process (byp…

Deno is a JavaScript, TypeScript, and WebAssembly runtime. From 2.7.0 to 2.7.1, A command injection vulnerability exists in Deno's node:child_process polyfill (shell: true mode) that bypasses the fi…

| Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32259 — ImageMagick has a possible stack buffer overflow in sixel encoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-16 and 6.9.13-41, when a memory allocation fails in the sixel encoder it would be possibl…

| Memory Corruption
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32240 — Cap'n Proto: Integer overflow in KJ-HTTP chunk size

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, when using Transfer-Encoding: chunked, if a chunk's size parsed to a value of 2^64 or larger, it would be tru…

| Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32239 — Cap'n Proto has an integer overflow in KJ-HTTP

Cap'n Proto is a data interchange format and capability-based RPC system. Prior to 1.4.0, a negative Content-Length value was converted to unsigned, treating it as an impossibly large length instead.…

| Misconfiguration
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32251 — Tolgee has an XXE Injection in Translation Import

Tolgee is an open-source localization platform. Prior to 3.166.3, the XML parsers used for importing Android XML resources (.xml) and .resx files don't disable external entity processing. An authenti…

| XML External Entity
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NA
CVE-2026-32249 — NFA regex engine NULL pointer dereference affects Vim < 9.2.0137

Vim is an open source, command line text editor. From 9.1.0011 to before 9.2.0137, Vim's NFA regex compiler, when encountering a collection containing a combining character as the endpoint of a chara…

| Memory Corruption
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.9 MEDIUM
CVE-2026-3497 — Linux OpenSSH GSSAPI Memory Corruption

Vulnerability in the OpenSSH GSSAPI delta included in various Linux distributions. This vulnerability affects the GSSAPI patches added by various Linux distributions and does not affect the OpenSSH u…

Remote | Memory Corruption
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.1 HIGH
CVE-2026-32247 — Graphiti vulnerable to Cypher Injection via unsanitized node_labels in search filters

Graphiti is a framework for building and querying temporal context graphs for AI agents. Graphiti versions before 0.28.2 contained a Cypher injection vulnerability in shared search-filter constructio…

Remote | Injection
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.5 HIGH
CVE-2026-32246 — Tinyauth vulnerable to TOTP/2FA bypass via OIDC authorize endpoint

Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC authorization endpoint allows users with a TOTP-pending session (password verified, TOTP not yet completed) to obtain …

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
6.5 MEDIUM
CVE-2026-32245 — Tinyauth's OIDC authorization codes are not bound to client on token exchange

Tinyauth is an authentication and authorization server. Prior to 5.0.3, the OIDC token endpoint does not verify that the client exchanging an authorization code is the same client the code was issued…

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
9.1 CRITICAL
CVE-2026-32242 — Parse Server OAuth2 adapter shares mutable state across providers via singleton instance

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 9.6.0-alpha.11 and 8.6.37, Parse Server's built-in OAuth2 auth adapter exports a singl…

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
4.4 MEDIUM
CVE-2026-32237 — @backstage/plugin-scaffolder-backend: Possible exposure of defaultEnvironment secrets usi…

Backstage is an open framework for building developer portals. Prior to 3.1.5, authenticated users with permission to execute scaffolder dry-runs can gain access to server-configured environment secr…

Remote | Information Disclosure
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
0.0 NONE
CVE-2026-32236 — @backstage/plugin-auth-backend: SSRF in experimental CIMD metadata fetch

Backstage is an open framework for building developer portals. Prior to 0.27.1, a Server-Side Request Forgery (SSRF) vulnerability exists in @backstage/plugin-auth-backend when auth.experimentalClien…

Remote | Server-Side Request Forgery
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
5.9 MEDIUM
CVE-2026-32235 — @backstage/plugin-auth-backend: OAuth redirect URI allowlist bypass

Backstage is an open framework for building developer portals. Prior to 0.27.1, the experimental OIDC provider in @backstage/plugin-auth-backend is vulnerable to a redirect URI allowlist bypass. Inst…

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.8 HIGH
CVE-2026-32232 — ZeptoClaw: Path boundary checks bypass via symlink, TOCTOU, and hardlink

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, there is a Dangling Symlink Component Bypass, TOCTOU Between Validation and Use, and Hardlink Alias Bypass. This vulnerability is fixed in 0.7.6.

Remote | Misconfiguration
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
8.2 HIGH
CVE-2026-32231 — ZeptoClaw: Generic webhook channel trusts caller-supplied identity fields; allowlist is c…

ZeptoClaw is a personal AI assistant. Prior to 0.7.6, the generic webhook channel trusts caller-supplied identity fields (sender, chat_id) from the request body and applies authorization checks to th…

Remote | Authentication
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
5.3 MEDIUM
CVE-2026-32230 — Uptime Kuma is Missing Authorization Checks on Ping Badge Endpoint, Leaks Ping times of m…

Uptime Kuma is an open source, self-hosted monitoring tool. From 2.0.0 to 2.1.3 , the GET /api/badge/:id/ping/:duration? endpoint in server/routers/api-router.js does not verify that the requested mo…

Remote | Information Disclosure
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
5.3 MEDIUM
CVE-2026-32142 — shopware/commercial: `/api/_info/config` route exposes information about licenses

Shopware is an open commerce platform. /api/_info/config route exposes information about licenses. This vulnerability is fixed in 7.8.1 and 6.10.15.

Remote | Information Disclosure
Mar 12, 2026 Mar 12, 2026
Mar 12, 2026
Mar 12, 2026
Showing 20 of 5440 Results